Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add pvliesdonk/markdown-vault-mcp --skill writing-release-notesgit clone --depth 1 https://github.com/pvliesdonk/markdown-vault-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pvliesdonk/markdown-vault-mcp/writing-release-notes)<a href="https://agentmods.dev/skills/pvliesdonk/markdown-vault-mcp/writing-release-notes"><img src="https://agentmods.dev/badge/skills/pvliesdonk/markdown-vault-mcp/writing-release-notes/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/pvliesdonk/markdown-vault-mcp/writing-release-notes"><img src="https://agentmods.dev/badge/skills/pvliesdonk/markdown-vault-mcp/writing-release-notes.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 3 findings, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Prompt Injection · line 8 Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.Fix: Audit all comments and invisible characters. Remove any instructions that direct the agent to perform unauthorized actions. Use plain, reviewable content.
- high Prompt Injection · line 268 Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.Fix: Audit all comments and invisible characters. Remove any instructions that direct the agent to perform unauthorized actions. Use plain, reviewable content.
- medium Excessive Agency · line 387 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00035 | $0.04691 |
| Opus 5 | $0.00017 | $0.02346 |
| Sonnet 5 | $0.00007 | $0.00938 |
| Haiku 4.5 | $0.00003 | $0.00469 |
Grade A, and why
writing-release-notes scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 412 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Writing release notes
The pages under docs/releases/ are the canonical human-facing narrative of
each release; the GitHub release body is a summary plus a link to them, and
CHANGELOG.md is the machine-written commit-level audit trail. This skill is
the contract for producing a page: what to research, what counts as evidence,
what the page looks like, and which gates it must pass. Every requirement
below was established empirically by trial runs recorded on
pvliesdonk/fastmcp-server-template#347; where this skill says "must", a trial
produced the failure the rule prevents.
Choose the mode
prepare-next: research through the selected release branch head and writedocs/releases/next.md.refresh-known-target: update an existingdocs/releases/X.Y.mdentry for the stable identity shared by an RC series.backfill/redraft: update a shipped canonical page.
Before research, record the repository, base branch, mode, stable target when known, previous stable tag, and range-end commit SHA. Ask the human for any value that cannot be derived unambiguously.
An existing page's <!-- notes-range-end: SHA --> watermark records where its
last accepted research ended. For prepare-next, RANGE_END is the selected
release branch head. For canonical refreshes and backfills, use the stable
identity and exact vX.Y.Z summary markers already present in the page.
Incremental research (patch and redraft modes)
The accepted page is the cache; do not re-research a range the page already covers. When the page carries the watermark:
- If the watermark SHA equals
RANGE_END, the page's researched content is already current: do no re-research and leave the prose alone. Say what you verified in the pull request body. - Otherwise research only
WATERMARK..RANGE_END(the same fan-out and evidence rules, over the delta), fold the findings into the existing narrative — extend a theme, add one, or leave prose untouched when the delta is stamps and mechanics — and verify claims the delta might have invalidated rather than re-deriving the whole page. - Always move the watermark to
RANGE_ENDwhen you touch the page, and write it (once, at the top of the page after the front matter or title) when you create a page.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 412 lines · 35 tokens per session scan A 84b29e5ec6f0
writing-release-notes is a skill published in the GitHub repository pvliesdonk/markdown-vault-mcp (32 stars, last pushed today), licensed MIT. It adds 35 tokens to every session and 4,691 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
mnemonic
Search local indexed markdown knowledge bases. Use when the user asks to find notes, dig up a concept from personal docs, cross-reference ideas across wikis, or answer from indexed local files. Triggers on "look up in notes", "search my docs", "what did I write about", "find in my vault", "check my index", "retrieve…
youtube-fetcher
Retrieve YouTube transcripts and subtitles, summarize or analyze what was said, or save an Obsidian-ready Markdown knowledge-base note with captions, creator metadata, chapters, language, and source provenance. Use for a YouTube URL or video ID when the request needs spoken content or an archival note. A bare YouTube…
link-memory
Use after important user-approved decisions, when durable context should be proposed or reviewed, and for explicit Link memory lifecycle work: remember, recall, review, update, archive, restore, forget, or explain local memories through the CLI without requiring MCP.
link-retrieve
Use before answering work that may depend on user memory, project history, source-backed notes, or prior decisions; retrieve compact Link context through the CLI without loading the whole wiki or requiring MCP.
link-ingest
Use when raw files are present, source pages look stale, or a user asks to ingest notes into Link; refresh source-backed wiki pages, propose memories, and validate updates through the CLI without MCP.
reduce
Extract structured knowledge from source material. Comprehensive extraction is the default — every insight that serves the domain gets extracted. For domain-relevant sources, skip rate must be below 10%. Zero extraction from a domain-relevant source is a BUG. Triggers on "/reduce", "/reduce [file]", "extract…